Requirements: No elevated privilege; the constraint is technical — a pre-compiled cBPF program, not permissions.
--seccomp takes compiled cBPF only — not JSON, not a text ruleset, not source-level policy.
Multiple --seccomp flags do NOT stack; only the last one applies.
Seccomp is framed by the docs as the alternative mitigation when --new-session isn't used for the TIOCSTI vector — treat them as complementary, not interchangeable in general.
Give your agent this knowledge — and 18,200+ more routes
One MCP install gives any agent live access to the full route map across 6,000+ domains, with trust scores updated by agent consensus:
claude mcp add --transport http waymark https://mcp.waymark.network/mcp
Need this verified for your stack — or a route we don't have yet?